CVE-2026-4270
Improper Protection of Alternate Path exists in the no-access and workdir feature of the AWS API MCP Server versions >= 0.2.14 and < 1.3.9 on all platforms may allow the bypass of intended file access restriction and expose arbitrary local file contents in the MCP client application context. To remediate this issue, users should upgrade to version 1.3.9.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.8
- CVSS vector
- CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
- EPSS probability
- 0.13%
- CWE
- CWE-424
- Published
- 2026-03-16
- Last modified
- 2026-03-16
Affected products
- AWS AWS API MCP Server
Weakness type
Related vulnerabilities
- CVE-2026-82586 — AshLua read operation aggregate bypasses the exposed-field allow-list, exposing private attributes
- CVE-2026-82754 — ash_authentication_oauth2_server aliases every protocol endpoint under /.well-known, bypassing path-scoped controls
- CVE-2026-86145 — PCRE2 before 10.48 allows a pcre2_dfa_match out-of-bounds write because reuse of a cached workspace...
- CVE-2026-58428 — Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939)
- CVE-2026-66756 — Apache Tika: unpack endpoint in tika-server allows configuration with unsecureFeatures=false
- CVE-2026-54423 — In OpenStack Ironic before 37.0.1, an Ironic user with the ability to deploy nodes using the IPMI...
- CVE-2026-0268 — Prisma Access Agent: Local Authenticated VPN Enforcement Bypass on Linux
- CVE-2026-0237 — Prisma Browser: Improperly Restricted Automation Bridge Allows Security Bypass